CVE-2025-23213 Information
Jan 30, 2025
cve
Description
Tandoor Recipes is an application for managing recipes planning meals and building shopping lists. The file upload feature allows to upload arbitrary files including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.
Reference
https://github.com/TandoorRecipes/recipes/commit/3e37d11c6a3841a00eb27670d1d003f1a713e1cf https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-56jp-j3x5-hh2w
Share on: